From owner-freebsd-security@FreeBSD.ORG Thu Jul 21 15:32:20 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E359C16A41F; Thu, 21 Jul 2005 15:32:20 +0000 (GMT) (envelope-from simon@zaphod.nitro.dk) Received: from zaphod.nitro.dk (port324.ds1-khk.adsl.cybercity.dk [212.242.113.79]) by mx1.FreeBSD.org (Postfix) with ESMTP id E889E43D82; Thu, 21 Jul 2005 15:32:04 +0000 (GMT) (envelope-from simon@zaphod.nitro.dk) Received: by zaphod.nitro.dk (Postfix, from userid 3000) id 7720711A79; Thu, 21 Jul 2005 17:32:03 +0200 (CEST) Date: Thu, 21 Jul 2005 17:32:03 +0200 From: "Simon L. Nielsen" To: Giorgos Keramidas Message-ID: <20050721153202.GF880@zaphod.nitro.dk> References: <42DCC503.5000408@ludd.ltu.se> <20050719213356.GA1614@gothmog.gr> <20050721101331.GB854@trit.org> <20050721102012.GG16179@beatrix.daedalusnetworks.priv> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="idY8LE8SD6/8DnRI" Content-Disposition: inline In-Reply-To: <20050721102012.GG16179@beatrix.daedalusnetworks.priv> User-Agent: Mutt/1.5.9i Cc: freebsd-security@freebsd.org, Joachim Str?mbergson , Dima Dorfman Subject: Re: Adding OpenBSD sudo to the FreeBSD base system? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 21 Jul 2005 15:32:21 -0000 --idY8LE8SD6/8DnRI Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2005.07.21 13:20:12 +0300, Giorgos Keramidas wrote: > My thoughts exactly. The only thing I'd like to add is that the port is > that importing it to the base system would probably require someone who > steps up and offers to maintain it as bugfixes/features are noticed in > the upstream source. But, I guess, this is more or less obvious. Personally I have a preference for not having it in the base system for the simple reason that we would need to make security advisories for it... and while I don't remember any grave holes, there certainly have been a few holes over the last year. --=20 Simon L. Nielsen --idY8LE8SD6/8DnRI Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (FreeBSD) iD8DBQFC37/yh9pcDSc1mlERAuCKAKCaq3Esh+BmsbQxLonx7CU3T5XNDgCdES/R DmECczuOlHgBW1YN0G/4ca8= =e4MY -----END PGP SIGNATURE----- --idY8LE8SD6/8DnRI--